You cannot copy content of this website, your IP is being recorded.

Healthcare websites and 18 ePHI items that should be protected for BAA

Healthcare websites and 18 ePHI items that should be protected for BAA

Under the HIPAA Privacy Rule’s Safe Harbor method (45 CFR § 164.514(b)(2)), there are 18 specific identifiers that turn health, treatment, or billing data into Protected Health Information (PHI). If your website collects or transmits any of these alongside health details (such as booking an appointment or submitting a contact form), it is considered electronic PHI (ePHI), requiring a Business Associate Agreement (BAA) with your vendors.

The 18 ePHI items you must protect are:

Personal & Contact Identifiers

  1. Names: Full names, initials, aliases, or family member names.
  2. Geographic subdivisions smaller than a state: Street addresses, cities, counties, precincts, and full ZIP codes. (Note: ZIP codes have a strict 3-digit aggregation rule for areas with fewer than 20,000 people).
  3. Dates (except year): Birth dates, admission dates, discharge dates, and dates of death. This also includes precise ages if the individual is over 89 years old.
  4. Telephone numbers: Any phone number tied to a user or patient account.
  5. Fax numbers: Medical or personal fax numbers.
  6. Email addresses: Patient or contact form emails.

Government & Account Identification Numbers

  1. Social Security Numbers (SSN): Full or partial SSNs.
  2. Medical record numbers (MRN): Chart numbers or electronic health record (EHR) identifiers.
  3. Health plan beneficiary numbers: Insurance member IDs, group numbers, or Medicare numbers.
  4. Account numbers: Billing account IDs, financial accounts, or patient ledger numbers.
  5. Certificate/license numbers: Driver’s licenses, professional medical licenses, or state IDs.

Device & Property Serial Numbers

  1. Vehicle identifiers: Vehicle Identification Numbers (VINs) and license plate numbers.
  2. Device identifiers and serial numbers: Serial numbers for medical equipment, implants, or mobile device tokens tracked by analytics apps.

Web-Native Identifiers (Critical for Healthcare Websites)

  1. Web Universal Resource Locators (URLs): Direct links to patient portals, user accounts, or uniquely tokenized file destinations.
  2. Internet Protocol (IP) addresses: Network addresses logged by your website server or third-party tracking pixels (e.g., Meta Pixel, Google Analytics) during user sessions.

Biometric & Visual Elements

  1. Biometric identifiers: Fingerprints, voice prints, or iris/retina scans.
  2. Full-face photographic images: Or any comparable photo/video format that clearly identifies an individual.

Others

  1. Any other unique identifier: Any unique identifying number, characteristic, or code that is not a standard investigator key and could point directly to one person. [1]

Warning for Healthcare Websites

Items 14 (URLs) and 15 (IP addresses) are captured automatically by default on almost every modern website. The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) heavily penalizes organizations that use unauthorized advertising trackers or analytics tools that collect website visitors’ IP addresses on booking pages, symptom checkers, or portals without a signed BAA.

Healthcare websites and 18 ePHI items that should be protected for BAA

Under the HIPAA Privacy Rule's Safe Harbor method (45 CFR § 164.514(b)(2)), there are 18 specific identifiers that turn health, treatment, or billing data into Protected Health Information (PHI). If your website collects or transmits any of these alongside health details (such as booking an appointment or submitting a contact form), it is considered electronic PHI (ePHI), requiring a Business Associate Agreement (BAA) with your vendors.
Healthcare websites and 18 ePHI items that should be protected for BAA

Under the HIPAA Privacy Rule's Safe Harbor method (45 CFR § 164.514(b)(2)), there are 18 specific identifiers that turn health, treatment, or billing data into Protected Health Information (PHI). If your website collects or transmits any of these alongside health details (such as booking an appointment or submitting a contact form), it is considered electronic PHI (ePHI), requiring a Business Associate Agreement (BAA) with your vendors.